tyler-smith.com · Questions & Answers

Our team members are using personal generative AI accounts to draft outgoing vendor agreements and negotiate purchase orders. How do we establish a strict policy to stop this shadow IT risk?

When team members use personal AI accounts to draft vendor agreements or negotiate purchase orders, they expose your company to massive legal and operational risks. Free public tools often retain your inputs to train their models, meaning your proprietary pricing, vendor terms, and operational vulnerabilities could enter the public domain. You must establish a clear, practical AI policy that governs external partner relations.

Start by mandating that all vendor communications and legal drafts go through company-approved, secure enterprise AI portals where data privacy is contractually guaranteed. Do not ban the technology entirely, as this only drives the behavior underground. Instead, provide your team with the right tools and establish clear boundaries.

Your policy must explicitly state that no contract, service level agreement, or pricing sheet can be sent to an outside party without a complete human review. The AI can draft the initial framework, but a qualified manager who owns that seat on the Accountability Chart must verify every line. This ensures that terms are realistic and that the machine has not hallucinated unapproved liabilities or pricing commitments.

Incorporate this policy directly into your employee handbook and review it during quarterly State of the Company meetings. By setting clear boundaries, you protect your supply chain and intellectual property, ensuring your operations remain secure and highly attractive to future buyers.

Category: AI-Powered Operations

← All questions